aboutcode-org / aboutcode-org/vulnerablecode
Collect commits from dependabot
- 主要言語
- Python
- スター
- 702
- フォーク
- 328
- 平均マージ
- 3日 8時間
- マージ済み PR(30日)
- 3
説明
We should mine and store the commits made from dependabot in vulnerablecode database.
- Get all the dependabot commits
- Check the package mentioned in that commit is vulnerable or not for example: https://github.com/KoraLinSar/python-socketio/commit/a79f81b8346ab58b012910375569c5d913f0146c this states `Bump sanic from 0.8 to 20.12.6 in /examples/server/sanic` here sanice@0.8 might be vulnerable which can be checked from vulnerablecode https://public.vulnerablecode.io/packages/pkg:pypi/sanic@0.8.0?search=sanic this means this commit is fixing a vulnerable package and the current release of that package can be marked as vulnerable.
- Also check if the commit is merged in main, sometimes dependabot commits might be changing the mock data in test files
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。